Summary
In short
- The UK now has three failure to prevent offences: bribery under the Bribery Act 2010, facilitation of tax evasion under the Criminal Finances Act 2017, and fraud under ECCTA, in force from 1 September 2025.
- All three provide a procedures-based defence, and in each the risk assessment is what makes proportionality arguable. Without it there is nothing to calibrate the procedures against.
- The Home Office guidance on failure to prevent fraud is more prescriptive than the earlier bribery and tax evasion guidance, and it states explicitly that risk assessment is the foundation for the other five principles.
- Being regulated elsewhere does not mean your existing procedures automatically qualify. The guidance is clear that existing compliance mechanisms are a starting point, not a defence.
- The failure to prevent fraud offence carries an unlimited fine, applies to large organisations across all sectors, and requires no proof of management involvement.
- Smaller organisations are affected indirectly: they may be associated persons of large organisations and face contractual requirements flowed down to them.
What it is
What it is
What is an anti-bribery risk assessment?
A structured assessment of where an organisation is exposed to bribery and corruption, by geography, sector, transaction type, business model and third party relationship, and what controls address each exposure. It informs the design of the whole programme, and under UK law it is the element on which the statutory defence rests.
Why does the assessment matter so much legally?
Because the UK failure to prevent offences provide a defence only where procedures were adequate or reasonable, and both standards are judged as proportionate to risk. Proportionality cannot be demonstrated without an assessment establishing what the risk was. Home Office guidance on the fraud offence states directly that a thorough risk assessment is the foundation and that all other principles should be informed by it.
When to use it
When to use it, and when not to
The assessment establishes exposure and calibrates the programme. It is not the programme, and it is not the due diligence performed on individual counterparties.
Use it for
- Establishing the organisation-wide exposure by geography, sector, transaction type and business model
- Assessing third party exposure: agents, distributors, consultants, customs brokers and joint venture partners
- Reviewing after entering a new market, acquiring a business, or changing the intermediary model
- Calibrating due diligence depth, approval thresholds and monitoring intensity to the assessed risk
- Evidencing proportionality for the statutory defences under UK failure to prevent offences
Not for
- Individual counterparty due diligence, which applies the assessment's conclusions to a specific third party
- The code of conduct and gifts and hospitality policy, which are controls the assessment informs
- Whistleblowing arrangements, which are a separate mechanism with their own requirements
- Payment and procurement fraud controls, which address a different offence with overlapping controls
- Sanctions and export control screening, which is a distinct regime with strict liability characteristics
Standards
What it is built against
Anti-bribery obligations combine a management system standard with criminal offences whose defences turn on the quality of the risk assessment.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 37001 cl.4.5 | Bribery risk assessment identifying, analysing, evaluating and prioritising bribery risk, reviewed regularly | Exposure |
| Bribery Act 2010 s.7 | Corporate offence of failure to prevent bribery, with adequate procedures as the defence | Header |
| Bribery Act guidance, principle 3 | Risk assessment as one of six principles underpinning adequate procedures | Exposure |
| Criminal Finances Act 2017 ss.45-46 | Failure to prevent facilitation of UK and foreign tax evasion, with reasonable procedures as the defence | Header |
| ECCTA 2023, failure to prevent fraud | In force 1 September 2025 for large organisations, with reasonable procedures as the only defence | Header |
| FCPA anti-bribery and accounting provisions | Prohibition on corrupt payments to foreign officials, plus books and records and internal controls | Controls |
| ISO 37001 cl.8.2 | Due diligence on transactions, projects, business associates and personnel proportionate to assessed risk | Controls |
| ISO 37001 cl.9.2 | Internal audit of the anti-bribery management system at planned intervals | Assurance |
What it does not cover
- Counterparty due diligence, which applies the assessment to a specific third party before engagement.
- Gifts, hospitality and facilitation payment policy, which are controls calibrated by the assessment.
- Whistleblowing arrangements, which operate independently and have their own protections and timescales.
- Sanctions and export control screening, a separate regime with different liability characteristics.
- The books and records controls required under the FCPA accounting provisions, which sit with finance.
Filling it in
Filling it in well
An assessment that supports a legal defence has to show its working. Four things determine whether it does.
Identify the specific interactions where bribery is plausible: permits, licences, inspections, customs clearance, tender processes, tax settlements and anything mediated by an agent paid on outcome. Then establish who performs them, through whom, and with what oversight. A country risk score tells you the weather; this tells you where the exposure sits.
All three UK offences turn on acts by associated persons: employees, agents, subsidiaries, and anyone performing services for or on behalf of the organisation. The assessment has to reach them, and the guidance is clear that smaller organisations may find themselves subject to requirements flowed down contractually because they are associated persons of someone larger.
The Home Office guidance states that organisations should not duplicate existing work, and equally that existing regulatory compliance mechanisms do not automatically amount to reasonable procedures. The correct approach is to map what exists against the risks this assessment identified and to record where the gaps are, rather than asserting that a regulated business is therefore compliant.
The defence is judged on procedures in place at the time of the offence. An assessment dated four years ago, covering a business that has since entered two markets and acquired a distributor, does not support proportionality for the current operation. Review annually and on any material change to markets, model or intermediaries.
Audit findings
Common audit findings
Findings here concern whether the assessment could actually support a defence.
| Finding | Clause | What fixes it |
|---|---|---|
| Assessment based on country risk indices with no transaction-level analysis. | ISO 37001 cl.4.5 | Identify the specific transactions and intermediaries where exposure arises. |
| Third parties and associated persons not covered. | Bribery Act s.7 | All three UK offences turn on associated persons; the assessment must reach them. |
| Existing regulatory compliance cited as evidence of reasonable procedures. | ECCTA guidance | Map existing controls against identified risks and record gaps; regulation is not a defence. |
| Assessment not reviewed after entering a new market or acquiring a business. | ISO 37001 cl.4.5 | Review on change; the defence is judged on procedures at the time of the offence. |
| Due diligence depth uniform rather than calibrated to assessed risk. | ISO 37001 cl.8.2 | Tier due diligence; uniform depth over-burdens low risk and under-examines high risk. |
| Fraud risk not assessed despite the September 2025 offence. | ECCTA | Extend the assessment to fraud committed for the organisation's benefit; it is a separate offence. |
| No top level commitment evidenced beyond a signed policy. | Bribery Act guidance, principle 1 | Evidence engagement: resourcing decisions, escalations handled, communication from leadership. |
| Training generic rather than targeted at the assessed high-risk roles. | ISO 37001 cl.7.3 | Target training at people performing the transactions the assessment identified. |
| Monitoring and review principle unaddressed. | Bribery Act guidance, principle 6 | Define what is monitored, how often, and what happens when something is found. |
| Assessment undated or unowned. | ISO 37001 cl.4.5 | Date, sign and own it; an undated assessment cannot evidence procedures at a point in time. |
Worked case
Case in point: the third offence nobody assessed for
The UK now has three failure to prevent offences. Bribery came first under the Bribery Act 2010, with adequate procedures as the defence. Facilitation of tax evasion followed under the Criminal Finances Act 2017, with reasonable procedures. The failure to prevent fraud offence under ECCTA came into force on 1 September 2025, applying to large organisations across all sectors, carrying an unlimited fine, with reasonable procedures as the only defence.
The Home Office guidance published in November 2024 was described by practitioners as remarkably prescriptive relative to its predecessors, and it states plainly that a thorough risk assessment is the foundation and that the other five principles should be informed by its results. The Serious Fraud Office signalled its intention to pursue the offence from the outset.
Many organisations arrived at September 2025 with a bribery risk assessment reviewed reasonably recently and no assessment at all of where fraud might be committed for the organisation's benefit. Those are overlapping but distinct exposures, and only one of them had been mapped.
Definitions
Definitions and key terms
- Associated person
- Anyone performing services for or on behalf of the organisation: employees, agents, subsidiaries, contractors and intermediaries.
- Adequate procedures
- The Bribery Act 2010 section 7 defence standard, judged against six principles and proportionate to risk.
- Reasonable procedures
- The defence standard under the tax evasion and fraud offences. The Home Office has indicated it is no more onerous than adequate.
- Facilitation payment
- A small payment to secure or expedite a routine government action. Illegal under the Bribery Act; a narrow FCPA exception exists.
- Six principles
- Top level commitment, risk assessment, proportionate risk-based procedures, due diligence, communication including training, and monitoring and review.
- Failure to prevent offence
- A corporate offence turning on an associated person's act, without requiring proof of management knowledge or intent.
- Red flag
- An indicator warranting enhanced scrutiny: unusual commission, request for payment to a third country, political connection, refusal of contract terms.
- Books and records provisions
- FCPA accounting requirements for accurate records and adequate internal accounting controls, enforced independently of bribery itself.
FAQ
Frequently asked questions
Why is the risk assessment the foundation of the defence?+
Because the defences require procedures that are adequate or reasonable, and both are judged as proportionate to the risk faced. Proportionality is unarguable without an assessment establishing what the risk was. Home Office guidance on the fraud offence states directly that a thorough risk assessment is the foundation and that the other principles should be informed by its results.
What changed on 1 September 2025?+
The failure to prevent fraud offence under the Economic Crime and Corporate Transparency Act 2023 came into force in England and Wales. It applies to large organisations across all sectors, makes them criminally liable where an associated person commits fraud intending to benefit the organisation, carries an unlimited fine, and provides reasonable fraud prevention procedures as the only defence. It requires no proof of management involvement.
Do our existing compliance procedures count?+
They are a starting point, not a defence. The guidance advises against duplicating existing work while making clear that existing regulatory compliance mechanisms do not automatically amount to reasonable procedures. The correct approach is to map what you have against the risks identified in this assessment and record where the gaps are.
Are small organisations affected?+
Directly, only where they meet the large organisation threshold. Indirectly, substantially: a smaller business may be an associated person of a large organisation and find fraud prevention requirements flowed down contractually. The practical effect is that the obligation propagates through supply chains well beyond the entities in scope.
How often should the assessment be reviewed?+
Annually as a minimum, and on any material change: entering a new market, acquiring a business, changing the intermediary model, or a significant change in the regulatory environment. The defence is judged on the procedures in place at the time of the offence, so an assessment describing a business you no longer are supports nothing.
The agents
What the agents do with it
The assessment is the foundation of three defences. What fails is the transaction detail nobody mapped and the review that lapsed after an acquisition.
Holds the assessment against markets, transaction types and third parties, and triggers review on acquisitions, new markets and intermediary changes.
Maps existing controls against assessed risks and surfaces the gaps, rather than allowing existing compliance to be asserted as coverage.
Extends assessment and due diligence to associated persons, including agents and intermediaries who are not suppliers in the usual sense.
Targets training at the roles performing the transactions the assessment identified, rather than delivering the same module to everyone.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Sources
Sources
- ISO 37001:2016 anti-bribery management systems, clauses 4.5, 8.2 and 9.2
- Bribery Act 2010 section 7 and Ministry of Justice guidance on adequate procedures
- Economic Crime and Corporate Transparency Act 2023, failure to prevent fraud, in force 1 September 2025
- Home Office guidance on failure to prevent fraud reasonable procedures, November 2024
- Criminal Finances Act 2017 sections 45 and 46, failure to prevent facilitation of tax evasion
- US Foreign Corrupt Practices Act, anti-bribery and accounting provisions